Skip to content
← Back to job listings

Staff Application Security Engineer

Abridge · San Francisco, United States

External listingfull-timeabout 2 months ago

About The Role

Join Abridge, a leading AI healthcare startup, as a Staff Application Security Engineer. In this role, you'll be a key technical leader, driving initiatives that shape our product, infrastructure, and engineering practices. You'll work cross-functionally with product and engineering teams to integrate security seamlessly, automate security capabilities and controls, and mentor others to build secure-by-default systems at scale. This position requires deep technical expertise, a builder's mindset, and excellent communication skills. Enjoy a remote work environment, flexible hours, unlimited PTO, and equity for all new employees.

  • Lead Threat Modeling and Design Reviews: Conduct advanced threat modeling and security architecture reviews for complex systems, new products, and platform initiatives.
  • Define Security Strategy: Define and implement the technical roadmap for the Application Security program, focusing on scalable assurance, proactive security measures, and setting clear standards and guardrails.
  • Mentor and Enable: Act as a subject matter expert and trusted advisor to product and engineering teams, providing mentorship on security features, product defense, secure coding practices, application architecture, and vulnerability remediation strategies.
  • Programming Fluency: Deep proficiency in one or more major programming languages (Python and NextJS a big plus) and a solid background in software development principles
  • Cloud & Containers: Extensive experience securing applications deployed in Cloud environments (GCP a big plus) and knowledge of containerization technologies (Kubernetes)
  • AI Security: Deep understanding of the security of AI and ML models, agents, and associated systems
  • Technical Depth: Expert-level knowledge of web application security techniques and principles, APIs, IAM (including identity, authentication/authorization, RBAC, ABAC), applied cryptography, etc
  • Experience: 10+ years of direct experience in an Application Security role, with a demonstrated history of designing and implementing security improvements at scale
  • Security Research: Proven experience contributing to or leveraging open-source security tools, publishing security research, managing bug bounty programs, and active engagement in the security industry
  • Cross-Functional Influence: Demonstrated ability to drive large, cross-functional technical projects that impact security posture across the entire organization
  • Data-Driven Security: Experience defining and utilizing security metrics to measure and report on the effectiveness of the AppSec program to both technical and executive audiences

This is an external listing. JobSpring does not represent or verify the employer. Report this listing